CVE-2020-13788: SSRF
Published Jul 15, 2020
·Updated
Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.
Affected Software
1 affected component
linuxfoundation Harbor<2.0.1
Event History
Jul 15, 2020
CVE Published
via MITRE·08:04 PM
Data Sourced
via MITRE·08:04 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-13788.
2
What is the severity of CVE-2020-13788?
The severity of CVE-2020-13788 is medium with a severity value of 4.3.
3
What is the description of CVE-2020-13788?
CVE-2020-13788 is a vulnerability in Harbor prior to 2.0.1 which allows Server-Side Request Forgery (SSRF) with the limitation that an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.
4
What software versions are affected by CVE-2020-13788?
Harbor versions up to and excluding 2.0.1 are affected by CVE-2020-13788.
5
How can I fix CVE-2020-13788?
To fix CVE-2020-13788, it is recommended to update to Harbor version 2.0.1 or later.